---
title: "Rotate commit signing key"
method: POST
path: "/api/v1/models/{modelId}/git/rotate-signing-key"
tags: ["Models"]
---

# Rotate commit signing key

`POST /api/v1/models/{modelId}/git/rotate-signing-key`

Rotate the commit signing keypair for a GitHub App connection and return the git configuration with the new commitSigningPublicKey to register on the committer’s GitHub user. Omni mints a fresh Ed25519 keypair unless signingPrivateKey supplies your own (with signingKeyPassphrase when encrypted), enabling zero-downtime rotation: register the matching public key on GitHub first, then set it here. The committer identity can be changed in the same call, so signing can be moved to a different GitHub user in one step. Commits already signed with the old key stay Verified only while the old public key remains registered on GitHub. Only valid for github_app auth.

## Path parameters

- `modelId` string, uuid, required — Model UUID

## Request body

- ModelsGitRotateSigningKeyBody
  - `commitSigningCommitterEmail` string, email, nullable — Verified email of the GitHub user that owns the registered signing key, written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterName.
  - `commitSigningCommitterName` string, nullable — Display name written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterEmail.
  - `signingKeyPassphrase` string — Passphrase for signingPrivateKey when it is encrypted. Omni uses it once to decrypt the key, then stores the key under its own encryption at rest; the passphrase itself is not retained.
  - `signingPrivateKey` string — Bring-your-own ED25519 signing private key in PEM format (as produced by `ssh-keygen -t ed25519`), used instead of an Omni-generated keypair. Enables zero-downtime rotation: register the matching public key on the GitHub user first, then set it here. RSA keys are rejected — commit signing is SSHSIG over ED25519. Must be non-blank when provided; omit it to have Omni mint a fresh keypair.

## Response `200`

Signing key rotated; response includes the new public key

- ModelsGitRotateSigningKeyResponse
  - `authMethod` 'ssh' | 'https_token' | 'github_app', required — Authentication method. "ssh" for deploy key, "https_token" for deploy token/PAT, "github_app" for a GitHub App installation.
  - `baseBranch` string, required — The target branch for Omni pull requests
  - `branchPerPullRequest` boolean, required — If true, all pull requests will create a branch in Omni, even those created outside of the tool
  - `cloneUrl` string, required — Clone URL of the git repository (SSH or HTTPS)
  - `commitSigningCommitterEmail` string, nullable, required — Committer email written into signed commits (github_app auth). Null when signing is not configured.
  - `commitSigningCommitterName` string, nullable, required — Committer display name written into signed commits (github_app auth). Null when signing is not configured.
  - `commitSigningPublicKey` string, nullable, required — SSHSIG signing public key to register on the committer’s GitHub user (github_app auth). Null for other auth methods.
  - `gitFollower` boolean, required — If true, the shared model is read-only and can only be updated by merging pull requests to the base branch
  - `gitServiceProvider` string, required — The git provider type
  - `githubAppInstallationId` string, nullable, required — GitHub App installation ID. Null unless github_app auth.
  - `modelPath` string, nullable, required — Path to model files in the repository
  - `publicKey` string, nullable, required — SSH public key for repository access (deploy key). Null for HTTPS token auth.
  - `requirePullRequest` 'always' | 'users-only' | 'never', required — When pull requests are required: "always" for all changes, "users-only" for user-initiated changes only, "never" for direct commits.
  - `sshUrl` string, required — Deprecated — use cloneUrl. Clone URL of the git repository.
  - `webUrl` string, nullable, required — Custom web URL for the git repository, or null if not set
  - `webhookSecret` string — Webhook secret for signature verification. Only included if requested via ?include=webhookSecret
  - `webhookUrl` string, required — Webhook URL to configure in your git provider

## Other responses

- `400` — Invalid signing key, passphrase, or committer fields
- `401` — Authentication required
- `403` — Permission denied
- `404` — Model not found or git not configured
- `422` — Model is not a GitHub App connection

---

[API](https://skmtc.net/omniapp/apis/omni-api.md) · [All operations](https://skmtc.net/omniapp/apis/omni-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/omniapp/omni-api/versions/de7cac8b5983/schema)
